ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Week in review: Attackers probing for vulnerable Exchange servers, RSA Conference 2020 coverage

criticalRansomware exploited in the wildimportance 60CVE-2020-0688CVE-2020-6418CVE-2019-15126

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-15126
An issue was discovered on Broadcom Wi-Fi client devices.

An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.

NVD description · AI analysis pending
3.17%
  • apple ipados
  • apple iphone os
  • apple mac os x
  • +1 more
CVE-2020-0688
RCE in Microsoft Exchange Server from Shared Install-Time Validation Keys

CVE-2020-0688 is a remote code execution vulnerability in Microsoft Exchange Server caused by the validation key not being uniquely created at install time, leaving deployments with a predictable, shared key (CWE-287, improper authentication). A remote attacker who can reach an affected Exchange server and knows the common install-time key can supply maliciously crafted, cryptographically signed payloads that the server trusts, triggering code execution without needing per-server secrets. Successful exploitation gives the attacker code execution on the Exchange server, which can be used to access mail data, move laterally, and stage follow-on activity; CISA notes known use in ransomware campaigns. All organizations running the affected on-premises Microsoft Exchange Server are in scope per CISA's listing, though the affected version range is not specified in the source data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, and EPSS rates 30-day exploitation probability at 100% (top percentile).

Do: Apply Microsoft's Exchange security updates addressing CVE-2020-0688 (released in February 2020) to every on-premises Exchange server, per CISA's required action. As an interim mitigation, configure a unique ASP.NET machineKey in each Exchange server's web.config instead of the default shared install-time key, and hunt for indicators of exploitation given the known ransomware use.

8.8100% KEV ransomware PoC ×2
  • Microsoft Exchange Server
masshundreds of thousands of on-premises Exchange servers (≈500,000)
CVE-2020-6418
Type Confusion in Google Chrome's V8 Engine Enables Heap Corruption

CVE-2020-6418 is a type confusion vulnerability (CWE-843) in V8, the JavaScript engine used in Google Chrome and Chromium, affecting versions prior to 80.0.3987.122. A remote attacker triggers it by persuading a user to open a crafted HTML page whose JavaScript causes V8 to mishandle object types (public PoCs reference a JSCreate side-effect issue), potentially leading to heap corruption. Successful exploitation can yield arbitrary code execution in the browser, a common stepping stone for further compromise on the victim's system. Any Chrome/Chromium deployment with the vulnerable V8 was affected, including Chromium packages shipped by Fedora, Red Hat Enterprise Linux, and Debian. The flaw was a zero-day exploited in the wild when patched in February 2020; it is listed in CISA KEV (added 2021-11-03) and carries a very high EPSS of 78.8%, making it a priority patch.

Do: Update Google Chrome to 80.0.3987.122 or later and confirm the running version via chrome://settings/help or chrome://version. Apply the updated Chromium packages from Fedora, Red Hat, and Debian on managed Linux endpoints and check whether any hosts still run pre-fix Chromium. Given the KEV listing and 78.8% EPSS, treat patching as urgent; as an interim mitigation on unpatched systems, limit untrusted web browsing or restrict JavaScript from untrusted sites.

8.879% KEV PoC ×2
  • Google Chrome prior to 80.0.3987.122
  • Google Chromium V8 (JavaScript engine component) prior to the fix delivered in Chrome 80.0.3987.122
  • Fedora Project Fedora (Chromium package) Chromium builds with vulnerable V8; distro-specific version numbers not provided in source data
  • +4 more
massbillions of users/installations (Chrome's global install base runs to billions, and at disclosure in February 2020 every Chrome user on a pre-80.0.3987.122…
Full article823 words · extracted from helpnetsecurity.com · click to collapse

Here’s an overview of some of last week’s most interesting news and articles:

RSA Conference 2020 coverage
Check out our microsite for related news, photos, product releases, and more.

Healthcare industry at greatest risk of data breach
The healthcare industry has significantly more exposed attack surfaces than any other industry surveyed, according to Censys’s research findings of cloud risks and cloud maturity by industry, revealed at RSA Conference 2020.

Attackers probing for vulnerable Microsoft Exchange Servers, is yours one of them?
CVE-2020-0688, a remote code execution bug in Microsoft Exchange Server that has been squashed by Microsoft in early February, is ripe for exploitation and could become a vector for ransomware groups in coming months, warns cybersecurity researcher Kevin Beaumont.

Almost three-quarters of all phishing sites now use SSL protection
The total number of phishing sites detected by the Anti-Phishing Working Group (APWG) worldwide in October through December 2019 was 162,155, following the all-time-high of 266,387 attacks recorded in July through September 2019.

OpenDXL Ontology: An open source language for connecting cybersecurity tools
The Open Cybersecurity Alliance (OCA) announced the availability of OpenDXL Ontology, the first open source language for connecting cybersecurity tools through a common messaging framework.

Google fixes another Chrome zero-day exploited in the wild
For the third time in a year, Google has fixed a Chrome zero-day (CVE-2020-6418) that is being actively exploited by attackers in the wild.

A new way for securing web browsers from hackers
A powerful new approach to securing web browsers is getting its first real-world application in the Firefox browser.

CWE list now includes hardware security weaknesses
The Mitre Corporation has released version 4.0 of the Common Weakness Enumeration (CWE) list, which has been expanded to include hardware security weaknesses.

By exploiting an LTE vulnerability, attackers can impersonate mobile phone users
Exploiting a vulnerability in the mobile communication standard LTE, researchers at Ruhr-Universität Bochum can impersonate mobile phone users. Consequently, they can book fee-based services in their name that are paid for via the mobile phone bill – for example, a subscription to streaming services.

Hacking has become a viable career, according to HackerOne
Not only are more hackers spending a higher percentage of their time hacking, they’re also earning a living doing it.

Changing the mindset of the CISO: From enforcer to enabler
With digital transformation investments expected to reach a staggering $7.4 trillion before 2023, organizations realize that they must disrupt their markets or risk being disrupted themselves. However, with digital transformation comes a multitude of cybersecurity-related challenges to overcome, and it’s up to the CISO to help businesses navigate the associated risks.

Shadow IoT: A growing threat to enterprise security
Zscaler released their second annual IoT report, compiled after analyzing their customers’ IoT transactions in the Zscaler cloud for two weeks. The company found 553 different IoT devices across 21 categories from 212 manufacturers.

Flaw affecting 1B+ Wi-Fi-enabled devices allows attackers to decrypt wireless network packets
ESET researchers have discovered Kr00k (CVE-2019-15126), a previously unknown vulnerability in Wi-Fi chips used in many client devices, Wi-Fi access points and routers.

97% of IT leaders worried about insider data breaches
A staggering 97% of IT leaders say insider breach risk is a significant concern, according to a survey by Egress.

Review: Specops Key Recovery
One of the more pressing risks linked to the use of mobile devices is the possibility of device loss or theft. If a device is lost, sensitive data (e.g., documents, account passwords) might get extracted and exposed.

Users still engaging in risky password, authentication practices
IT security practitioners are aware of good habits when it comes to strong authentication and password management, yet often fail to implement them due to poor usability or inconvenience, according to Yubico and Ponemon Institute.

ENISA publishes procurement guidelines for cybersecurity in hospitals
The EU Agency for Cybersecurity (ENISA) published a cybersecurity procurement guide for hospitals.

Modern malware is increasingly leveraging evasive behaviors
Modern malware is increasingly leveraging evasive behaviors, a new report by VMware Carbon Black released at RSA Conference 2020 has revealed. The report uncovers the top attack tactics, techniques, and procedures (TTPs) seen over the last year and provides specific guidance on ransomware, commodity malware, wipers, access mining and destructive attacks.

eSentire Annual Threat Intelligence Report: 2019 Perspectives and 2020 Predictions
Eliminate guesswork and get in-depth insights and practical recommendations for navigating the ever-changing cybercrime landscape. This data-laden, incident-rich report delivers insider information on the players, their motivations, tactics and targets so you can make informed security strategy decisions.

Download: The Ultimate Security Pros’ Checklist
The Ultimate Security Pros’ Checklist provides you with a concise and actionable way to keep track of all your operational, management and reporting tasks.

A new RCE in OpenSMTPD’s default install, patch available
Less than a month after the patching of a critical RCE flaw in OpenSMTPD, OpenBSD’s mail server, comes another call to upgrade to the latest version, as two additional security holes have been plugged.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/03/01/week-in-review-attackers-probing-for-vulnerable-exchange-servers-rsa-conference-2020-coverage/